Framework overlap

Does PCI SSF cover ISO 45001?

You hold PCI SSF and have been told to do ISO 45001. Here is how much overlaps, control by control.

13% of ISO 45001 you already have

PCI SSF already covers about 13% of ISO 45001, leaving 34 of 39 controls as genuinely new work.

Already covered 0 Likely covered 5 New work 34

No control in PCI SSF maps directly to one in ISO 45001. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in PCI SSF reaches these. This is the list to scope.

ISO45001-01
OH&S policy and commitment
ISO45001-04
OH&S objectives and action plans
ISO45001-05
Worker consultation and participation
ISO45001-06
Elimination and substitution of hazards
ISO45001-07
Engineering and administrative controls
ISO45001-08
Personal protective equipment management
ISO45001-09
Emergency preparedness and response
ISO45001-10
Contractor and visitor safety management
ISO45001-10.2
Incident, nonconformity and corrective action
ISO45001-10.3
Continual improvement
ISO45001-11
Incident investigation and reporting
ISO45001-12
OH&S monitoring and measurement
ISO45001-13
Internal OH&S audit program
ISO45001-14
Management review and continual improvement
ISO45001-4.1
Understanding the organization and its context
ISO45001-4.2
Needs and expectations of workers and interested parties
ISO45001-4.3
Determining scope of OH&S management system
ISO45001-5.2
OH&S policy
ISO45001-5.3
Roles, responsibilities and authorities
ISO45001-5.4
Consultation and participation of workers
ISO45001-6.1.2
Hazard identification and assessment of risks
ISO45001-6.1.3
Determination of legal and other requirements
ISO45001-6.1.4
Planning action
ISO45001-6.2
OH&S objectives and planning to achieve them
ISO45001-7.2
Competence
ISO45001-7.3
Awareness
ISO45001-7.4
Communication
ISO45001-8.1.2
Eliminating hazards and reducing OH&S risks
ISO45001-8.1.4
Procurement and contractors
ISO45001-8.2
Emergency preparedness and response
ISO45001-9.1
Monitoring, measurement, analysis and evaluation
ISO45001-9.1.2
Evaluation of compliance
ISO45001-9.2
Internal audit
ISO45001-9.3
Management review
Show the 5 you already have
ISO45001-02
Hazard identification and risk assessment
ISO45001-03
Legal and regulatory compliance
ISO45001-15
Corrective actions and lessons learned
ISO45001-5.1
Leadership and commitment
ISO45001-8.1.3
Management of change

How this is calculated

Already covered means a mapping runs from a control in PCI SSF to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition